CVE-2026-102331(google / android)

LOWCVSS 9.6 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Buffer overflow in ANGLE in Google Chrome on on Android prior to 154.0.8037.92 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-122

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • android
  • chrome

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Peaked 1d ago at 3 mentions (2026-09-29); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
androidchrome

1 version affected across 2 products

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-09-29: 3Mentions · 2026-09-30: 109-2909-30
Referenced assets4 URLs
Full discourse4 posts
  • Dark Web Intelligence@DailyDarkWeb

    🚨 CHROME STABLE UPDATE — 33 SECURITY FIXES INCLUDING CRITICAL ANGLE CVE Google issued a new Stable Channel Update for Desktop on September 29, 2026, advancing Chrome 154 with 33 security fixes. • Versions: 154.0.8037.92/.93 (Windows/Mac); 154.0.8037.92 (Linux) • Rollout: gradual Stable channel over coming days/weeks • Critical: CVE-2026-102331 — buffer overflow in ANGLE (reported by @mfx) • High-severity highlights include type confusion / buffer issues in V8 (CVE-2026-102299, CVE-2026-102323, CVE-2026-102326, CVE-2026-102328, CVE-2026-102321, CVE-2026-102302), use-after-free bugs across Views, Passwords, FullScreen, Bluetooth, and PictureInPicture, plus GPU / WebGPU / WebGL memory-safety fixes • Distinct from the September 22 Chrome 154 Stable promotion (108 fixes) already covered on @DailyDarkWeb ⚠️ Analyst Note: This is the official Google Chrome Releases Stable Channel Update for Desktop dated September 29, 2026 — a new mid-cycle security build, not a rehash of the Sep 22 154 launch. Google often keeps bug details and links restricted until a majority of users are updated. No KEV listing for these CVEs at handoff. Update Chrome promptly via Help → About Google Chrome (or your managed update channel). Official: https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01807488085.html #DDW #DarkWeb #CyberSecurity #ThreatIntelligence #Chrome #CVE #CVE2026102331

    1101014.8K
    205.7K followersView on X
  • NEXSIGHT@NEXSIGHTNEWS

    Chromeが154.0.8037.92へセキュリティ更新 — 32件修正、CriticalのANGLE欠陥CVE-2026-102331に対処 https://cyber.nexsight.co/articles/2026/09/30/chrome-154-8037-92-security-update-angle-cve-2026-102331-2026-09-30/

    0000038
    75 followersView on X
  • Daily CyberSecurity@Daily_CyberSec

    Google's Chrome security update 154.0.8037.92 fixes 33 flaws, including critical ANGLE bug CVE-2026-102331 and six V8 issues. Update Chrome now. #Chrome #GoogleChrome #ChromeSecurityUpdate #CVE2026102331 #V8 #BrowserSecurity #ANGLE #PatchNow https://securityonline.info/chrome-154-security-update/

    00000330
    13.0K followersView on X
  • VulDB 🛡@vuldb

    There is a new vulnerability with elevated criticality in Google Chrome (CVE-2026-102331) https://vuldb.com/vuln/411731

    00000110
    2.3K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
OSgoogleandroid---
Appgooglechrome---

Explore more